What we collect
- What you submit for an audit: the public repo URL you point us at, files read from it, and any text you paste. This is the raw material of your report; without it there is nothing to audit.
- Your email address, if you create an account or buy a report. Sign-in is a magic link, so there are no passwords to store or leak.
- Payment records are handled by Stripe. Card numbers never touch our servers; we keep only the transaction reference.
How your sources are treated
- Secrets are redacted before any model call. API keys and credential-shaped strings found in your sources are stripped out before anything is sent to a language model.
- Your submissions produce your report, nothing else. We do not use them to train models and we do not sell them.
- Reports are private by default. Your report lives at an unguessable link, carries a noindex instruction for search engines, and is published nowhere unless you share the link.
Cookies and tracking
- We set a session cookie when you sign in and a small preference cookie for your light/dark theme choice. That is the list.
- No ad trackers, no third-party ad cookies, no selling of browsing data. Anti-bot checks on the audit form use Cloudflare Turnstile. If we measure traffic, we use cookieless, aggregate analytics.
Who else touches data
The service runs on Cloudflare. Payments run through Stripe. Sign-in and receipt emails are sent through a transactional email provider. Audits call a language model API (Claude, by Anthropic) with your redacted sources to produce your report. Each provider receives only what its job requires.
Deletion and questions
Want your account, reports, or submitted sources deleted? Email meter@bullshitmeter.dev from the address on the account and we will delete them. Same address for any question this page did not answer.